การเชื่อมต่อแพลตฟอร์ม
ปรับปรุงล่าสุด: 6 กันยายน 2569
หน้านี้อธิบายอย่างโปร่งใสว่าแอป SellHub เชื่อมต่อกับแต่ละแพลตฟอร์มอย่างไร เข้าถึงข้อมูลอะไร ขอสิทธิ์ (scope / API permission group) ใดบ้าง และเพราะเหตุใด เพื่อให้ร้านค้าตัดสินใจก่อนกดอนุญาต และเพื่อประกอบการตรวจสอบแอปของแพลตฟอร์ม
หลักการร่วมทุกแพลตฟอร์ม
- เชื่อมต่อผ่านหน้าอนุญาต (OAuth) อย่างเป็นทางการของแพลตฟอร์มเท่านั้น — เราไม่ขอรหัสผ่านร้านค้า
- ขอเฉพาะสิทธิ์ที่จำเป็นต่อฟีเจอร์ที่เปิดใช้ (ร้านค้า สินค้า ออเดอร์ สต๊อก และโลจิสติกส์เมื่อเปิดใช้) ไม่ขอสิทธิ์การเงิน/การชำระเงิน แชท หรือโฆษณา
- ทุกคำขอ API ลงลายเซ็น HMAC-SHA256 และส่งผ่าน HTTPS เท่านั้น เรียกจากเซิร์ฟเวอร์ของเราโดยตรง
- ข้อมูลผู้ซื้อใช้เพื่อการจัดส่งและเอกสารการขายของร้านค้านั้นเท่านั้น และถูกปิดบังหลังออเดอร์เสร็จสิ้นตาม นโยบายความเป็นส่วนตัว
- โทเค็นถูกต่ออายุอัตโนมัติและถูกลบทันทีเมื่อร้านค้ายกเลิกการเชื่อมต่อ หรือเมื่อได้รับ webhook แจ้งการเพิกถอนจากแพลตฟอร์ม
- รองรับ webhook ที่ตอบกลับ HTTP 200 ทันทีและประมวลผลเบื้องหลัง พร้อม retry แบบ backoff และเคารพ rate limit ของแพลตฟอร์ม
Shopee
| คอนโซลนักพัฒนา | Shopee Open Platform |
|---|---|
| หน้าอนุญาต (OAuth) | https://open.shopee.com/auth?partner_id=<partner_id>&auth_type=seller&redirect_uri=<callback>&response_type=code&state=<state> (หรือ https://partner.shopeemobile.com/api/v2/shop/auth_partner) |
| API host | https://partner.shopeemobile.com/api/v2 (ทุกภูมิภาครวมประเทศไทย) |
| Redirect URL (Authorization) | https://<odoo-host>/marketplace/oauth/shopee/callback |
| Push mechanism callback URL | https://<odoo-host>/marketplace/webhook/shopee/<id> |
สิทธิ์ที่ขอและเหตุผล
| Scope / API group | ใช้ทำอะไร |
|---|---|
| App type: ERP System — Shop module (v2.shop.get_shop_info, v2.auth.token/get, access_token/get) | ระบุร้านที่เชื่อมต่อ ขอและต่ออายุโทเค็น |
| Product module (v2.product.get_item_list, get_item_base_info, update_stock) | ดึงรายการสินค้าเพื่อจับคู่ SKU และอัปเดตสต๊อกกลับ |
| Order module (v2.order.get_order_list, get_order_detail) | ดึงออเดอร์และรายละเอียดผู้รับเพื่อสร้างใบสั่งขาย/ใบส่งของ |
| Logistics module (v2.logistics.*) — เมื่อเปิดใช้ฟีเจอร์จัดส่ง | ดึงเลขพัสดุ/สถานะจัดส่ง และพิมพ์ใบปะหน้า |
ข้อมูลที่เข้าถึง
- ข้อมูลร้าน: shop_id, ชื่อร้าน, ภูมิภาค, สถานะและวันหมดอายุการอนุญาต
- สินค้า: item_id, SKU, ชื่อ, ราคา, รูป, จำนวนคงเหลือ
- ออเดอร์: order_sn, สถานะ, รายการสินค้า, ยอดเงิน, ข้อมูลผู้รับ (ชื่อ เบอร์ ที่อยู่) เพื่อการจัดส่ง — เก็บไม่เกิน 90 วันตาม Shopee Data Protection Policy
Webhook ที่สมัครรับ
- Push code 3: order_status_push
- Push code 1: shop_authorization_push (แจ้งเมื่อร้านยกเลิกการอนุญาต → ลบโทเค็นทันที)
- Push code 4: tracking_no_push (เมื่อเปิดใช้ฟีเจอร์จัดส่ง)
ยกเลิกการอนุญาตจากฝั่ง Shopee
Shopee Seller Centre → บัญชี (Account) → พาร์ทเนอร์แพลตฟอร์ม (Platform Partner) → SellHub → ยกเลิกการเชื่อมต่อ (Separate / Deactivate) (https://seller.shopee.co.th/) — คู่มือ Shopee: https://seller.shopee.co.th/edu/article/5884 — ชื่อเมนูอาจต่างกันตามเวอร์ชันของ Seller Centre
Lazada
| คอนโซลนักพัฒนา | Lazada Open Platform |
|---|---|
| หน้าอนุญาต (OAuth) | https://auth.lazada.com/oauth/authorize?response_type=code&force_auth=true&country=th&redirect_uri=<callback>&client_id=<app_key> |
| API host | https://api.lazada.co.th/rest (ประเทศไทย) · โทเค็นผ่าน https://auth.lazada.com/rest |
| Callback URL | https://<odoo-host>/marketplace/oauth/lazada/callback |
| Message Service callback URL | https://<odoo-host>/marketplace/webhook/lazada/<id> |
สิทธิ์ที่ขอและเหตุผล
| Scope / API group | ใช้ทำอะไร |
|---|---|
| Seller API group (GET /seller/get) | ระบุร้านและประเทศของร้านที่เชื่อมต่อ |
| Product API group (GET /products/get, POST /product/price_quantity/update) | ดึงรายการสินค้าเพื่อจับคู่ SKU และอัปเดตสต๊อก/ราคากลับ |
| Order API group (GET /orders/get, GET /orders/items/get) | ดึงออเดอร์และรายการสินค้าในออเดอร์เพื่อสร้างใบสั่งขาย |
| Logistics API group — เมื่อเปิดใช้ฟีเจอร์จัดส่ง | ดึงสถานะจัดส่งและเลขพัสดุ |
ข้อมูลที่เข้าถึง
- ข้อมูลร้าน: seller_id, ชื่อร้าน, ประเทศ (country_user_info)
- สินค้า: item_id, SKU, ชื่อ, ราคา, รูป, จำนวนคงเหลือ
- ออเดอร์: order_id, สถานะ, รายการสินค้า, ยอดเงิน, ข้อมูลผู้รับแบบปิดบัง (masked) ตามค่าเริ่มต้นของ Lazada เพื่อการจัดส่ง — เราไม่ขอสิทธิ์ Unmask
Webhook ที่สมัครรับ
- Trade order status (Message Service)
- Reverse order status
- Token expiry alert
ยกเลิกการอนุญาตจากฝั่ง Lazada
Lazada Seller Center → Settings → Third Party App → Connected → Deauthorize (แอปประเภท ERP ที่สมัครผ่าน Service Marketplace: My Service → ยกเลิกการสมัคร) (https://sellercenter.lazada.co.th/) — ชื่อเมนูอาจต่างกันตามเวอร์ชันของ Seller Center
TikTok Shop
| คอนโซลนักพัฒนา | TikTok Shop Partner Center |
|---|---|
| หน้าอนุญาต (OAuth) | https://services.tiktokshop.com/open/authorize?service_id=<service_id>&state=<state> |
| API host | https://open-api.tiktokglobalshop.com (API version 202309+) |
| Redirect URL | https://<odoo-host>/marketplace/oauth/tiktok/callback |
| Webhook URL | https://<odoo-host>/marketplace/webhook/tiktok/<id> |
สิทธิ์ที่ขอและเหตุผล
| Scope / API group | ใช้ทำอะไร |
|---|---|
| Shop Authorized Information — seller.shop.info (GET /authorization/202309/shops) | ระบุร้าน ภูมิภาค และ shop_cipher ที่ใช้เรียก API |
| Product Basic + Product Modify (inventory) — seller.product.* (POST /product/202309/products/search, /inventory/update) | ดึงรายการสินค้าเพื่อจับคู่ SKU และอัปเดตสต๊อกกลับ |
| Order Information — seller.order.info (POST /order/202309/orders/search) | ดึงออเดอร์และรายละเอียดผู้รับเพื่อสร้างใบสั่งขาย/ใบส่งของ |
| Fulfillment Basic / Logistics Basic — เมื่อเปิดใช้ฟีเจอร์จัดส่ง | ดึงข้อมูลพัสดุ เลขพัสดุ และสถานะจัดส่ง |
ข้อมูลที่เข้าถึง
- ข้อมูลร้าน: shop_id, ชื่อร้าน, ภูมิภาค, shop_cipher, granted_scopes
- สินค้า: product_id, SKU, ชื่อ, ราคา, รูป, จำนวนคงเหลือ
- ออเดอร์: order_id, สถานะ, รายการสินค้า, ยอดเงิน, ข้อมูลผู้รับ (ชื่อ เบอร์ ที่อยู่) เพื่อการจัดส่ง
Webhook ที่สมัครรับ
- ORDER_STATUS_CHANGE
- SELLER_DEAUTHORIZATION (แจ้งเมื่อร้านยกเลิกการอนุญาต → ลบโทเค็นทันที)
- UPCOMING_AUTHORIZATION_EXPIRATION (แจ้งล่วงหน้า 30 วันก่อนสิทธิ์หมดอายุ)
ยกเลิกการอนุญาตจากฝั่ง TikTok Shop
TikTok Shop Seller Center → App Store → My apps and incidents → SellHub → Cancel authorization (https://seller-th.tiktok.com/) — TikTok Shop จะส่ง webhook SELLER_DEAUTHORIZATION มายัง SellHub เพื่อให้ลบโทเค็นอัตโนมัติ
ขั้นตอนการเชื่อมต่อ (สำหรับร้านค้า)
- เข้าสู่ระบบ SellHub → เมนู ร้านค้า → เชื่อมต่อร้านใหม่ แล้วเลือกแพลตฟอร์ม
- ระบบพาไปยังหน้าอนุญาตของแพลตฟอร์ม เข้าสู่ระบบด้วยบัญชีผู้ขายของคุณและกดยืนยัน
- แพลตฟอร์มส่งคุณกลับมายัง SellHub พร้อมรหัสอนุญาต ระบบแลกเป็นโทเค็นและดึงข้อมูลร้านค้า
- เลือกคลังสินค้าและตั้งค่าการซิงค์ จากนั้นระบบเริ่มดึงสินค้าและออเดอร์อัตโนมัติ
ดูข้อมูลแอปสำหรับผู้ตรวจสอบที่ ข้อมูลแอป · วิธียกเลิกและลบข้อมูลที่ การขอลบข้อมูล
English summary
SellHub connects Shopee, Lazada and TikTok Shop stores only through each platform's official OAuth authorization page and signed (HMAC-SHA256) HTTPS API calls made from our own servers. We request only the scopes needed for the features a merchant enables: shop info (identify the store and manage tokens), product listings and inventory (SKU mapping and stock updates), orders (create sales orders and deliveries, including the buyer's name, phone and shipping address required for fulfilment) and, when enabled, logistics (tracking numbers and shipping status). We do not request finance/payment, chat or advertising scopes. We subscribe to order-status and authorization-status webhooks, acknowledge them immediately and process them asynchronously. Tokens are refreshed automatically and deleted as soon as a merchant disconnects or revokes the app from the seller center. Buyer data is used solely for that merchant's fulfilment and is masked after order completion as described in our Privacy Policy.